Extension WordPress
Vulnérabilités Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, page 4
Cette page rassemble les failles publiées pour Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
73 fiches
Ultimate Member < 2.0.4 – Insecure Direct Object Reference
The Ultimate Member plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions prior to version 2.0.4. This is due to bypass access restriction via unspecified vectors. This makes it possible for authenticated attackers to modify…
[*, 2.0.4)
2.0.4
10/05/2018
Ultimate Member <= 2.0.6 – Multiple Cross-Site Request Forgery Issues
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
[*, 2.0.7)
2.0.7
23/04/2018
Ultimate Member <= 2.0.10 – Authenticated Cross-Site Scripting
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.
[*, 2.0.11)
2.0.11
23/04/2018
Ultimate Member <= 2.0 – Cross-Site Scripting
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
*-2.0
2.0.4
14/02/2018
Ultimate Member <= 2.0.3 – Cross-Site Scripting
core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
[*, 2.0.4)
2.0.4
14/02/2018
Ultimate Member <= 1.3.83 – Shortcode Injection
The Ultimate Member plugin for WordPress is vulnerable to Executing Arbitrary WordPress Shortcodes in versions up to, and including, 1.3.83. This is due to 'ultimatemember_frontend_modal' AJAX action allowing for the execution of the 'do_shortcode()' function. This makes it…
*-1.3.83
1.3.84
17/04/2017
Ultimate Member <= 1.3.75 – Missing Authorization to Password Reset
The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 1.3.75. This makes it possible for unauthenticated attackers to change the passwords of any user…
*-1.3.75
1.3.76
06/12/2016
Ultimate Member <= 1.3.64 – Local File Inclusion
The Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.64 via the 'page' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the…
[*, 1.3.65)
1.3.65
10/07/2016
Ultimate Member <= 1.3.39 – Cross-Site Scripting
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
[*, 1.3.40)
1.3.40
06/04/2016
Ultimate Member <= 1.3.28 – Reflected Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.
[*, 1.3.29)
1.3.29
02/12/2015
Ultimate Member <= 1.3.17 – Cross-Site Scripting
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
*-1.3.17
1.3.18
20/08/2015
Ultimate Member 1.2.98 – 1.2.997 – Reflected Cross-Site Scripting
The Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in versions 1.2.98 through 1.2.997 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
1.2.98-1.2.997
1.3.0
18/06/2015
Ultimate Member < 1.0.84 – Authorization Bypass to Arbitrary File Upload/Delete
The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ultimatemember_remove_file() function in versions up to, and including, 1.0.83. This makes it possible for unauthenticated attackers to delete or…
[*, 1.0.84)
1.0.84
10/03/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.